cbcvebase.
CVE-2021-21986
published 2021-05-26

CVE-2021-21986: The vSphere Client (HTML5) contains a vulnerability in a vSphere authentication mechanism for the Virtual SAN Health Check, Site Recovery, vSphere Lifecycle…

PriorityP269critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
12.92%
95.9th percentile
The vSphere Client (HTML5) contains a vulnerability in a vSphere authentication mechanism for the Virtual SAN Health Check, Site Recovery, vSphere Lifecycle Manager, and VMware Cloud Director Availability plug-ins. A malicious actor with network access to port 443 on vCenter Server may perform actions allowed by the impacted plug-ins without authentication.

Affected

5 ranges
VendorProductVersion rangeFixed in
vmwarecloud_foundation>= 3.0 < 3.10.2.13.10.2.1
vmwarecloud_foundation>= 4.0 < 4.2.14.2.1
vmwarevcenter_server
vmwarevcenter_server
vmwarevcenter_server

Detection & IOCsextracted from sources · hover to see the quote

port443
  • Monitor for unauthenticated requests to vCenter Server on port 443 targeting the Virtual SAN Health Check, Site Recovery, vSphere Lifecycle Manager, and VMware Cloud Director Availability plug-in endpoints, as exploitation requires no credentials.
  • Focus detection on the vSphere Client (HTML5) authentication mechanism for the listed plug-ins; unauthenticated actions against these plug-ins are indicative of exploitation.
  • ·The Virtual SAN Health Check plug-in is enabled by default in vCenter Server, broadening the attack surface to all default deployments.
  • ·Affected products include VMware Cloud Foundation, VMware vCenter Server, and vSphere — all deployments of these products should be assessed for exposure.

CVSS provenance

nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.